Macro packmacro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.
Pentesting BibleLearn ethical hacking.Learn about reconnaissance,windows/linux hacking,attacking web technologies,and pen testing wireless networks.Resources for learning malware analysis and reverse engineering.
BackdorosbackdorOS is an in-memory OS written in Python 2.7 with a built-in in-memory filesystem, hooks for open() calls and imports, Python REPL etc.
SnoopSnoop — инструмент разведки на основе открытых данных (OSINT world)
PwndropSelf-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
1earn个人维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
PerunPerun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
Poshc2A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
ChashellChashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.
DiamorphineLKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
Lockdoor Framework🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
PezorOpen-Source PE Packer
NishangNishang - Offensive PowerShell for red team, penetration testing and offensive security.
Sherlock🔎 Hunt down social media accounts by username across social networks
PayloadsallthethingsA list of useful payloads and bypass for Web Application Security and Pentest/CTF
Vipermetasploit-framework 图形界面 / 图形化内网渗透工具
Crossc2generate CobaltStrike's cross-platform payload
SlackpirateSlack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
Stowaway👻Stowaway -- Multi-hop Proxy Tool for pentesters
MxtractmXtract - Memory Extractor & Analyzer
Repo SupervisorScan your code for security misconfiguration, search for passwords and secrets. 🔍
Gtfobins.github.ioGTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
OctopusOpen source pre-operation C2 server based on python and powershell
HershellHershell is a simple TCP reverse shell written in Go.
FireelffireELF - Fileless Linux Malware Framework
Wadcoms.github.ioWADComs is an interactive cheat sheet, containing a curated list of Unix/Windows offensive tools and their respective commands.
FoureyeAV Evasion Tool For Red Team Ops
Emp3r0rlinux post-exploitation framework made by linux user
0xsp Mongoosea unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and privilege escalations attacks, replicate the tactics and techniques of an advanced adversary in a network.
A Red Teamer DiariesRedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Pidense🍓📡🍍Monitor illegal wireless network activities. (Fake Access Points), (WiFi Threats: KARMA Attacks, WiFi Pineapple, Similar SSID, OPN Network Density etc.)
Impost3r👻Impost3r -- A linux password thief
Cobalt strike extension kitAttempting to be an all in one repo for others' userful aggressor scripts as well as things we've found useful during Red Team Operations.
TtpsTactics, Techniques, and Procedures
Redteam ResearchCollection of PoC and offensive techniques used by the BlackArrow Red Team
LolbasLiving Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
OverlordOverlord - Red Teaming Infrastructure Automation
MicrosoftWontFixListA list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021 (and SpoolSample ;-))
BadAssMacrosBadAssMacros - C# based automated Malicous Macro Generator.
gtfoSearch for Unix binaries that can be exploited to bypass system security restrictions.